GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Anthropic Responds to Open Source Controversy: Opposes Full Ban on Open Models, Advocates for Restrictions on Chips and Model Distillation

Anthropic CEO Dario Amodei has responded to the controversy over open-weight models, stating that the company has never advocated for a total ban on open models. Previously, companies including OpenAI, Google, and SpaceX joined the open-source coalition, while Anthropic was the only major frontier model company not to sign on.Amodei acknowledged that open-weight models can lower costs, promote competition, and support customer self-deployment. He stated that open models without dangerous capabilities can be considered a "public good."However, he believes that open models are not necessarily safer, nor do defenders necessarily gain more advantages over attackers. Once model weights are made public, security restrictions may be removed and cannot be revoked.Anthropic proposed three alternative measures, including restricting the flow of advanced chips and manufacturing equipment to China, cracking down on industrial-scale model distillation, and requiring all models that reach a certain capability threshold—whether open-source or closed-source—to undergo testing for cyber attacks, biological risks, and alignment.

Jensen Huang: Establish Open Security AI Alliance to Strengthen Cyber Defense Capabilities with Open Models

NVIDIA CEO Jensen Huang stated that attackers have begun using frontier AI, and defenders similarly need to establish a frontier AI ecosystem composed of the best open-source and closed-source models, and leverage the global community to enhance defense capabilities.

BitMart to End 9 Years of Exchange Operations, BMX Plunges 81% in a Week

crypto exchange BitMart announced it will gradually wind down its trading platform business after nine years of operation. The platform halted new user registrations, deposits, and order placements at 01:30 UTC on July 26. All spot and derivatives trading will cease on August 26, and the platform is scheduled to officially shut down on January 31, 2027. BitMart stated that withdrawals will remain open, but checks related to identity, devices, sanctions, and funding sources may slow processing speeds. The company attributed the closure to its operational status, market conditions, and future strategic direction. Its native token, BMX, has fallen 81% over the past week to $0.057, bringing its market cap down to $19.6 million. BitMart previously suffered a loss of $196 million in December 2021 due to a hot wallet vulnerability, and covered the customer losses. Perpetual contract platform BitMEX also recently announced it will shut down after 11 years of operation, making BitMart the second major crypto exchange to announce a closure within a week.

Senator Lummis Champions the CLARITY Act to Combat Lazarus Group and Other Crypto Illegal Activities

According to Bitcoin.com, U.S. Senator Cynthia Lummis is pushing hard for the CLARITY Act to complete Senate voting before Congress adjourns. Section 303 of the bill grants the Treasury Department the authority to impose targeted digital asset sanctions on foreign jurisdictions, while Section 305 allows exchanges to freeze suspicious transactions for up to 180 days. On-chain data shows that North Korea's Lazarus Group stole approximately $643 million in the first half of 2026, accounting for two-thirds of the total global crypto theft during the same period ($972 million), including a $285 million attack on Drift Protocol in April and a $292 million attack on the KelpDAO cross-chain bridge. The group's cumulative theft amount has reached $6.75 billion since 2019. Currently, Galaxy Research has lowered the probability of the CLARITY Act passing within 2026 to 30%. The bill still requires 60 votes to advance, meaning at least 7 Democratic senators need to vote across party lines in support.

Cryptocurrency May Become Primary Target of Quantum Computing Attacks, Governance Speed Poses Greatest Risk

According to CoinDesk, Eddy Zervigon, CEO of quantum computing security infrastructure company Quantum Xchange, stated that cryptocurrencies, due to their decentralized nature, will become the "canary in the coal mine" for quantum computing attacks—that is, the area where vulnerabilities will be exposed first. Latest assessments by Google researchers show that the number of physical qubits required to break Bitcoin's elliptic curve encryption has decreased 20-fold compared to previous estimates, and multiple institutions have brought forward the expected date of "Q-Day" (the day quantum computers can break existing encryption systems) to 2029. Deutsche Digital Assets pointed out that the real risk lies not in the encryption technology itself, but in the speed of governance—Bitcoin upgrades require 90% miner consensus, which has historically triggered hard forks (such as the 2017 SegWit upgrade leading to the birth of Bitcoin Cash), whereas traditional financial institutions only need a board resolution to complete encryption infrastructure migration. Additionally, experts caution that the quantum threat is not a binary event that "arrives suddenly on a certain day"; even if quantum computers require months to crack data, as long as the cracking is completed while the data is still valuable, the threat is established.

Triple-A Treasury Wallet Hacked, Approximately $11.8 Million Lost

According to Cointelegraph, Singapore stablecoin payment company Triple-A confirmed its treasury wallet was accessed without authorization, with on-chain investigator Specter estimating losses at approximately $11.8 million. The company stated that customer funds are held in separate trust accounts and were not affected by this incident, and the relevant losses will be covered by the company's own financial reserves. Triple-A has currently restored all services and is collaborating with cybersecurity experts, blockchain forensic agencies, and the Singapore Police Force to investigate and track the stolen assets.

Polymarket probability of "effective ceasefire between the US and Iran before July 31" rises to 59%, up 19% in a single day

The PPP Prediction Market Tool monitoring shows that the probability of "effective ceasefire between the US and Iran before July 31" on Polymarket has risen to 59%, up 19% in a single day.This event will settle as "Yes" if the US takes no qualifying military action against Iran for 14 consecutive days before the specified deadline; otherwise, it will settle as "No."Qualifying military actions include only US-initiated airstrikes or surface-to-surface missile attacks that directly strike Iranian territory, including bombs, air-to-surface missiles, air-launched drones, cruise missiles, and ballistic missiles.Actions not counted include intercepted or destroyed munitions, surface-to-air missiles, small-scale skirmishes, ground operations, cyber attacks, naval shelling, artillery attacks, and unexecuted threats or authorized actions.If there is a dispute regarding the occurrence, attribution, or timing of a military action, the event will await a consensus formed by official information and credible media before being adjudicated. If differences persist after three full calendar days, a comprehensive judgment will be made based on all available information at that time.Settlement will be based on official information from the US and Iranian governments and military, as well as credible media reports.Join the PPP Signal Push Community to stay ahead and seize the opportunity.

Garden Finance Hacked, Loss of Approximately $450,000 USDT

According to Cointelegraph, the cross-chain bridging and atomic swap protocol Garden Finance temporarily took its application offline after detecting abnormal activity on July 27. Blockchain security firm Blockaid disclosed that attackers exploited a vulnerability in Garden Finance's Hash Time Locked Contracts (HTLC), stealing a total of approximately $450,000 worth of USDT across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.

WEMIX Stablecoin Hacked, Approximately $6.25 Million WEMIX$ Abnormally Outflowed

According to "Digital Assets", South Korean blockchain platform WEMIX released an official announcement on July 27, acknowledging a security incident involving its stablecoin WEMIX$ (WEMIX Dollar) smart contract. The incident occurred at 6:18 PM on July 26, when the owner permissions of the WEMIX$ smart contract were hijacked, resulting in approximately $6.25 million (approximately 87 million KRW) worth of WEMIX$ being abnormally minted and transferred to external addresses. WEMIX stated that it has identified the addresses suspected of being used in the attack and is conducting on-chain tracking, while collaborating with major exchanges and blockchain security agencies to monitor the flow of stolen assets, and will cooperate with law enforcement agencies if necessary.

ZachXBT Calls on Telegram Users to Support Channel Upgrade: Seeks to Disable Ads Due to Frequent Scam Advertisements

Odaily news "On-chain detective" ZachXBT posted in his personal channel, stating that Telegram continues to allow scam advertisements to be displayed to subscribers in his channel, impacting user experience and posing potential security risks.ZachXBT stated that if users are Telegram Premium members and wish to support upgrading his channel, they can help it reach the required level by using the channel's Boost function, thereby unlocking the ability to disable ads. Currently, the channel needs to reach Level 50 to enable the ad-disabling option.ZachXBT has long focused on scams, hacker attacks, and on-chain fund tracking within the crypto industry, and has repeatedly exposed incidents involving phishing attacks, fake projects, and fund theft.This time, he raised concerns about Telegram's advertising mechanism, arguing that the platform allowing scam advertisements to appear in crypto community channels may increase the risk of users encountering malicious links and fraudulent activities.

WEMIX confirms security incident: contract ownership may have been compromised, users advised to trade with caution

the WEMIX team has issued an announcement stating it is urgently investigating a potential security incident involving the WEMIX 3.0 network. Signs have been detected suggesting that contract ownership may have been compromised. The relevant team is currently verifying the facts and assessing the impact of the incident, and will release the investigation results and subsequent response measures as soon as possible based on the progress of the investigation. Until further official updates are released, WEMIX reminds users to exercise caution regarding unverified information and to maintain a high level of vigilance when transacting or investing in related assets.

Wemix Network may have suffered a security exploit of over $700,000

according to on-chain detective Specter's monitoring, Wemix Network may have suffered a security exploit of over $700,000, with the relevant address being 0xC921...7EA2.

Anthropic 称 Opus 5 在浏览器场景下几乎免疫提示词注入攻击

Anthropic 宣布其 Opus 5 模型在浏览器智能体场景中几乎免疫提示词注入攻击。在 129 个测试场景中,攻击成功率为零;在 Gray Swan 通用提示词注入测试中,15 次尝试后的成功率从 Opus 4.8 的 5.5% 降至 2.0%。零成功率仅在 Claude Cowork 等产品开启 Auto Mode 时实现,该模式叠加了输入扫描与执行拦截两层防御。提示词注入被视为 AI 智能体面临的最大安全隐患之一,此次改进或标志着该问题在特定场景下得到有效缓解。

The latest draft of the CLARITY Act proposes a white hat hacker reward mechanism to encourage the disclosure of security vulnerabilities.

The latest draft of the U.S. Senate's CLARITY Act adds new incentive provisions for white hat hackers, proposing to reward individuals who discover and responsibly disclose cybersecurity vulnerabilities to strengthen digital asset infrastructure security.

Anthropic states Opus 5 is the model in its lineup most difficult to attack via prompt injection.

Anthropic stated in the Opus 5 system card that this model is the least susceptible to prompt injection attacks to date. According to prompt injection evaluation and red teaming test results, Opus 5 demonstrates stronger resistance against malicious prompt injections. Prompt injection is one of the core risks in the field of AI security, where attackers bypass the model's safety constraints through carefully designed inputs to induce the model to perform unintended behaviors. Anthropic disclosed relevant evaluation details on page 73 of the system card.

Thailand SEC Files Criminal Complaint Against Bitkub and Two Former Directors Over 2021 False Reporting Case

According to The Nation Thailand, the Thai Securities and Exchange Commission has filed a criminal complaint with the Economic Crime Suppression Division against digital asset exchange Bitkub and its two former directors, alleging false statements in daily net capital reports submitted after the 2021 hacking incident. The incident resulted in the theft of approximately 1.7 billion baht worth of digital assets. The regulator believes that Bitkub failed to accurately reflect asset losses and related changes during the period from May to October 2021.

US Department of Commerce Evaluates Kimi K3, Claims U.S. Still Leads, But Report Notes Test Was Not Fully Equivalent

the U.S. Department of Commerce's AI Standards and Innovation Center, in collaboration with the UK AI Safety Institute, tested the cyber attack capabilities of Kimi K3, emphasizing that "the United States still leads."However, the value of the evaluation is debated due to limitations in the testing scope. Due to hosting environment constraints, Kimi K3 only participated in partial testing, with its overall cyber capabilities estimated primarily based on 41 exploit benchmarks. In contrast, other models underwent more comprehensive testing, resulting in a larger margin of error for Kimi K3's results.In the exploit testing, Kimi K3 scored approximately 32%, higher than GLM-5.2's 24%, but lower than the average of approximately 76% for leading U.S. models. In a simulated attack chain test, Kimi K3 completed an average of 17 out of 32 steps in the attack chain and successfully breached the network once in 10 attempts, while U.S. frontier models completed an average of 28.5 steps.The report notes that Kimi K3 already possesses a certain level of autonomous attack capability, and its security guardrails did not prevent the model from developing exploits or executing attacks. However, the report also emphasizes that the testing scope was limited.

研究:Kimi K3 网络攻击测试得分 32.2%,落后美国前沿模型超 40 个百分点

英国人工智能安全研究所与美国人工智能标准与创新中心联合评估显示,Moonshot AI 的 Kimi K3 可在缺乏实质性阻拦的情况下协助执行漏洞利用开发和模拟网络攻击,但其整体网络安全能力仍明显落后于美国领先模型。

OKX Jointly Releases H1 2026 Web3 Security and Risk Control Report with Elliptic, SlowMist, and OttoSec

according to official sources, OKX, in collaboration with Elliptic, SlowMist, and OttoSec, has released the "H1 2026 Web3 Security and Risk Control Report." The report indicates that the focus of Web3 attacks is shifting from smart contract code to more complex scenarios such as signature processes, user devices, operational infrastructure, and AI Agents.Data shows that in the first half of 2026, OKX's risk control system intercepted over 5.7 million high-risk transactions, including approximately 2.41 million related to hacking and theft, about 1.48 million phishing-related transactions, and roughly 990,000 fraud-related transactions. OKX Web3's on-chain intelligence label library now boasts over 1.1 billion labels, covering more than 420 chains. It has also integrated capabilities such as address screening, transaction monitoring, and sanctioned address control into infrastructure like DEX and Exchange OS.Furthermore, in terms of user protection, OKX has intercepted over 7 million risky website visits, completed more than 200,000 device risk detections, identified over 60,000 high-risk Apps, and blocked or alerted on over 4 million high-risk signature operations. The report also introduces the "proactive risk control" design in scenarios such as Exchange OS, Outcomes, RWA, and Agentic Wallet.

Lien Finance Suffers Attack Resulting in Approximately $542,000 Loss; Attacker Exploits Vulnerability to Drain USDC

According to SlowMist monitoring, the decentralized finance protocol Lien Finance suffered an attack. The attacker exploited a smart contract vulnerability to mint unbacked bond tokens and stole approximately $542,000 worth of USDC. Leveraging this vulnerability, the attacker successfully minted new, non-anomalous BondTokens without burning the corresponding input bonds. Subsequently, the attacker exchanged the tokens for USDC via a pre-authorized address, ultimately transferring approximately 542,144.63 USDC from the victim's address. Analysis indicates that the incident was essentially caused by a verification flaw in the bond token exchange logic, which allowed the attacker to bypass asset collateral constraints and mint unsupported assets.